Canadian Senate Chamber, known as the "Red Chamber", August 5, 2022.

(Photo by Hutima via Wikimedia Commons/CC BY-SA 4.0 DEED)

Listen to Article Summary:


On 18 June 2026, Members of the Canadian Parliament voted on amendments to a surveillance bill without debating most of them, and without the public being told what those amendments contained. 

The next day, the House passed Bill C-22, the Lawful Access Act, bundled into a single motion with several other bills, with no further debate and no recorded vote, as Members of Parliament left Ottawa for the summer. It now sits with the Senate, which begins its study this month.

You're already part of the story.

For 6 years, readers like you have kept Spheres independent and youth-led. If this piece mattered to you, join our Sphere of Influence — from $5/month.

Join the Sphere →

For a bill that would reshape how police and intelligence agencies access the digital lives of Canadians, the manner of its passage was striking.

What is Bill C-22?

Bill C-22 gives law enforcement and the Canadian Security Intelligence Service (CSIS) new powers to obtain data from telecommunications and online companies and requires those companies to build systems that make such access technically possible. 

Part 1 amends the Criminal Code and the CSIS Act to let police or public officers ask a telecommunications provider, without a court order, whether it has served a specific customer or account. Part 2 creates a new law, the Supporting Authorized Access to Information Act, or SAAIA, which forces “electronic service providers” to develop advanced surveillance capabilities and to retain user metadata for up to six months.

Lawful access is the power to compel that information from phone and internet companies during an investigation. The debate over C-22 turns on one question: how much of it is justified, and with how much oversight?

Governments across the world have spent the past decade arguing that encryption has put evidence beyond investigators’ reach. Australia legislated compelled technical assistance in 2018. The United Kingdom last year demanded backdoor access to Apple’s encrypted cloud storage, prompting the company to withdraw the feature from British customers rather than comply. Canada’s own attempt in 2012 collapsed under public backlash, and allies weighing similar laws will be watching what passes this time.

From Bill C-2 to Bill C-22

This is the government’s second attempt. The same powers first appeared in June 2025 as Parts 14 and 15 of Bill C-2, the Strong Borders Act, an omnibus bill mixing immigration, border, and surveillance measures. They drew immediate backlash for their extreme breadth from privacy advocates, civil liberties groups, the legal community, and the opposition parties.

Royal Canadian Mounted Police turning asylum seekers away at Roxham Road in Champlain, NY, August 14, 2017.
(Photo by Daniel Case via Wikimedia Commons/CC BY-SA 3.0 DEED)

Facing near-universal criticism, the government split the bill. The immigration measures advanced separately as Bill C-12, which drew its own criticism. The lawful access provisions returned in March 2026 as a standalone Bill C-22, with some of the most contested elements narrowed. But as the Canadian Bar Association noted, the consultations focused on “fixing” the earlier version rather than on whether the powers were necessary at all.

Canada’s Case For Safety

The government frames C-22 as a long-overdue modernization. In its backgrounder, Public Safety Canada states that law enforcement and CSIS have worked for decades with outdated laws that have not kept pace with digital technology, and that investigations are sometimes abandoned as a result. 

Without consistent technical standards, the department argues, Canada risks becoming an “intercept haven” for threat actors, and the bill would align it with G7 and Five Eyes allies.

Public Safety Minister Gary Anandasangaree has maintained that the bill simply modernizes lawful access so that police can investigate modern crime, and that it does not compel companies to weaken encryption or create systemic vulnerabilities. His office has rejected claims that the bill enables surveillance, arguing that tech companies are “misinterpreting” it. 

The government also points to the oversight built in: ministerial orders require the Intelligence Commissioner’s approval, providers can seek judicial review, and the minister must publish an annual report.

Constitutional Failures Amid Metadata Retention 

Yet, concerns continue to grow. The strongest objections centre on two mechanisms. 

The first is metadata retention. Metadata is data about your communications rather than their content: who you contacted, when, for how long, and from where. C-22 originally allowed the government to require a year of retention on every user, and sustained pushback cut that maximum to six months

The concession that the concerns were substantive, since governments do not amend bills to fix problems they believe do not exist. But six months of indiscriminate retention remains a significant shift. Pooled together, it can reveal a person’s movements, contacts, religious practice, and political views, which is why a Citizen Lab and Canadian Civil Liberties Association analysis described the government as collecting sensitive data unnecessarily.

Section 8 of the Canadian Charter of Rights and Freedoms protects against “unreasonable search and seizure.” Several of C-22’s powers rest on “reasonable grounds to suspect,” the lowest threshold in Canadian law, rather than the higher “reasonable grounds to believe” that normally governs production orders. 

The Canadian Civil Liberties Association says more than one aspect of the bill is “almost certainly constitutionally fatal,” singling out metadata retention as an indiscriminate seizure inconsistent with Section 8. With this, constitutional challenges are widely expected.

Who Gains Access Without End-to-End Encryption?

The second mechanism is technical capability. SAAIA lets the government require providers to build systems that enable law enforcement access, which it insists does not mean backdoors. The CBA, reading the bill’s text, disagreed, writing that “a plain reading” of the relevant section “and the lack of guardrails says otherwise.” 

End-to-end encryption, used by apps like Signal, is designed so a company cannot read a message and can comply with a legal duty to provide access. Security experts warn that criminals and hostile states can also find any access point built for police, a risk shown by the recent “Salt Typhoon” breach of United States telecom interception systems.

There is also the question of who is covered. The definition of “electronic service provider” is broad enough to capture almost any entity that creates, stores, or transmits information electronically, and the Canadian Bar Association noted it could reach hotels, clinics, universities, and law offices.

Why it Matters Beyond the Experts

Signal has said it would leave the Canadian market rather than comply. The Toronto-based VPN provider Windscribe would relocate its headquarters out of Canada, and NordVPN and DuckDuckGo have stated they may withdraw services.

Committee room for Parliamentary proceedings. This room is dedicated to Parliamentary Committees dicussing hearings, inquiries, and clause-by-clause study of bills, such as Bill C-22. Ottawa, September 2, 2019.
(Photo by Sean Marshall via Flickr/CC BY-NC 2.0 DEED)

Even so, larger companies’ stake is structural. Apple, which uses encryption to secure users’ health data, messages, photos, and finances, told the parliamentary committee that a backdoor built into an encrypted device can be walked through by anyone. 

Google told the same committee that the bill goes further than the laws of Canada’s allies and could facilitate foreign interference, and Meta has raised similar concerns. They also object that ministerial orders can be issued in secret, without prior judicial review, leaving them unable to tell users honestly how their data is protected.

The debate also extends across the border. The bill is widely linked to a potential data-sharing agreement with the United States under the American CLOUD Act, which critics warn could expose Canadians’ data to weaker privacy protections.

What Next?

Bill C-22 is not yet law. The Senate can do what the House did not: study it in the open and propose amendments with a recorded vote at the end. Public Scrutiny already cut the retention period in half.

Abandoning modernization is not the answer, since police and CSIS face a real challenge. But the Senate should fix three things before passage.

First, split the bill. Part 1 updates powers Parliament has debated before. Part 2 builds something new, a regime of mandatory retention and government-ordered surveillance capability, and it is the source of nearly all the constitutional and cybersecurity concern, and it deserves its own study.

Second, write the encryption promise into the law. If the government is right that the bill does not permit backdoors, saying plainly that no company can be ordered to weaken or bypass encryption costs nothing and closes the gap experts say the wording leaves open.

Third, be precise about scope and threshold. The definition of “electronic service provider” should be narrowed to the telecom and internet companies the bill targets, and the powers resting on reasonable suspicion should be raised to reasonable grounds to believe, the standard courts normally demand.

Whether C-22 protects Canadians or simply watches them more closely will depend on the changes the Senate is well positioned to make.

Edited by Isaac Code